CVE-2026-44231
published 2026-07-20CVE-2026-44231: RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information…
PriorityP260critical9.1CVSS 3.1
AVNACLPRLUINSCCHILAL
EPSS
0.41%
34.2th percentile
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bestpractical | request_tracker | < 5.0.10 | 5.0.10 |
| bestpractical | request_tracker | >= 6.0.0 < 6.0.3 | 6.0.3 |
| bestpractical | rt | < 5.0.10 | 5.0.10 |
| bestpractical | rt | — | — |
| ubuntu | request-tracker5 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Request Tracker vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 4.6
CVE-2026-44231 [MEDIUM] Request Tracker vulnerabilities
Title: Request Tracker vulnerabilities
Summary: Several security issues were fixed in Request Tracker.
Aleksander Iwicki discovered that Request Tracker did not properly sanitize
the search "Page" URL parameter. A remote attacker could possibly use this
issue to conduct a reflected cross-site scripting attack. (CVE-2026-6841)
It was discovered that Request Tracker did not properly sanitize user-
controlled data written to spreadsheet exports of search results. A remote
attacker could possibly use this issue to conduct a spreadsheet
(CSV/formula) injection attack, causing spreadsheet applications to
interpret crafted values as formulas or macros when the file is opened.
(CVE-2026-41073)
It was discovered that Request Tracker did not properly validate input
incorporated into database que
VulDB
Best Practical RT up to 5.0.9/6.0.2 REST API information disclosure
vuldb·2026-07-20·CVSS 9.1
CVE-2026-44231 [CRITICAL] Best Practical RT up to 5.0.9/6.0.2 REST API information disclosure
A vulnerability, which was classified as problematic, was found in Best Practical RT up to 5.0.9/6.0.2. This vulnerability affects unknown code of the component REST API. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2026-44231. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44231 rt: privilege escalation and information disclosure via REST 2.0 user collection endpoint [fedora-all]
bugzilla·2026-07-20·CVSS 9.1
CVE-2026-44231 [CRITICAL] CVE-2026-44231 rt: privilege escalation and information disclosure via REST 2.0 user collection endpoint [fedora-all]
CVE-2026-44231 rt: privilege escalation and information disclosure via REST 2.0 user collection endpoint [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints.
Bugzilla
CVE-2026-44231 rt: privilege escalation and information disclosure via REST 2.0 user collection endpoint
bugzilla·2026-07-20·CVSS 9.1
CVE-2026-44231 [CRITICAL] CVE-2026-44231 rt: privilege escalation and information disclosure via REST 2.0 user collection endpoint
CVE-2026-44231 rt: privilege escalation and information disclosure via REST 2.0 user collection endpoint
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
2026-07-20
Published